HomeSecurityTELUS investigates possible employee data leak

TELUS investigates possible employee data breach

Canada's second-largest telecommunications company, TELUS, is investigating a possible data breach after a threat actor shared samples of what appeared to be employee data online. The malicious actor then posted screenshots that apparently show private source code repositories and payroll records held by the company.

See also: Clasiopa group uses new Atharvan malware in its attacks

TELUS

See also: Guide from the NSA: How to protect home networks

TELUS has not yet discovered any evidence of unauthorized access to corporate or retail customer information and continues to monitor this potential incident.

Private source code and employee information are now available for purchase!

On February 17, an individual maliciously posted a list of alleged TELUS employees (containing names and emails ) available for purchase on a cybercriminal marketplace .

The forum post claimed that TELUS had suffered a major data breach, resulting in over 76,000 different emails and detailed internal information about each employee being extracted from its API

While BleepingComputer was unable to confirm the accuracy of the threat actor's claims, the small sample posted by the vendor has valid names and email addresses that correspond to current TELUS employees, particularly software developers and technical staff.

See also: Giant company Dole faces ransomware attack

On Tuesday, February 21, a malicious actor had posted another message on an online forum promising to sell TELUS' private GitHub repositories and source codes along with the company's confidential payroll information

TELUS investigates possible employee data breach

The vendor's latest post highlights that the repositories contain several key elements, including backend and frontend information , AWS keys and Google auth keys, source code , and more!

The vendor proudly proclaims that the stolen source code contains the company's "sim-swap-api," which will allow attackers to carry out SIM swap attacks.

Despite the hacker's claims of a "COMPLETE Breach" and his intentions to sell all data related to Telus, it is too early to definitively verify that such an incident took place at TELUS or to rule out a possible breach by a third-party vendor.

TELUS employees and customers should be aware of any suspicious emails, messages or phone calls they receive and avoid contacting them.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS